Standard 90-day vulnerability disclosure policy is likely dead thanks to AI, expert warns that AI can weaponize patches in 30 minutes — LLM-assisted bug-hunting ushers in a new cyberworld order
Source
Published
TL;DR
AI GeneratedAI-assisted code scanning tools are accelerating the discovery and exploitation of software vulnerabilities, rendering the traditional 90-day disclosure policy ineffective. Security researcher Himanshu Anand warns that AI can weaponize patches within 30 minutes, leading to a new cyberworld order where developers need to prioritize security measures like LLM-assisted bug-hunting. The rapid identification of vulnerabilities by AI-powered tools raises concerns about the effectiveness of current security practices, prompting Anand to advocate for immediate fixes for critical security issues. While open-source software benefits from quick patch distribution, closed-source software may face challenges as AI tools become more adept at identifying vulnerabilities.